6.9
CVE-2025-11674 - PiExtract|SOOP-CLM - Server-Side Request Forgery
SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information.
8.7
CVE-2025-10558 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIE…
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-10557 - Stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative …
A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-10556 - Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specif…
A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-10552 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENC…
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.6
CVE-2025-11673 - PiExtract |SOOP-CLM - Hidden Functionality
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
9
CVE-2025-9976 - OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Rel…
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
6.9
CVE-2025-11672 - EBM Technologies|Uniweb/SoliPACS WebServer - Missing Authentication
Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.
5.3
CVE-2025-11667 - code-projects Automated Voting System add_candidate_modal.php. sql injection
A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has b…
6.9
CVE-2025-11671 - EBM Technologies|Uniweb/SoliPACS WebServer - Missing Authentication
Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as account names and IP addresses.